Skip to content

Latest commit

 

History

History
 
 

Kukulkan

Kukulkan

Kukulkan

Description

This is basically a slimmed down version of SILENTTRINITY.

Kukulkan provides a C# DLL & EXE that embeds an IronPython engine allowing you to run IronPython scripts natively on Windows 10.

The Payload Server is used for C2: it hosts the needed assemblies, 'jobs' & handles output.

C2 Comms are performed over HTTPS (server also supports HTTP2), everything is encrypted using ECDHE with AES-256 & HMAC-SHA256, including the initial stage :).

The reasoning behind making this is to provide researches/red-teamers/pentesters a way of experimenting with the idea without having all the overhead of installing SILENTTRINITY which is not yet stable.

Additionally this is (i think?) 100% opsec safe, since the project provides .NET assemblies this can be used with other C2 platforms such as CobaltStrike.

Usage:

Usage: Kukulkan.exe <URL>

<URL> is the URL to the payload server (e.g. https://172.16.164.1/)

Disclaimer

I am by no means a crypto guru, if I implemented something wrong in the comms feel free to yell at me on Twitter or open an issue ticket (better yet a PR!).